Cerberus is an Android banking trojan operated as a malware-as-a-service offering and later widely reused after its source code leaked publicly in 2020. First publicly documented in 2019 after reportedly being used privately beforehand, it targets Android 5 and later devices and is designed primarily for banking fraud, credential theft, and broader device compromise. Cerberus became notable both for its commercial underground distribution model and for the large ecosystem of derivative malware families that followed its leak, including code-related successors and forks such as ERMAC and other Cerberus-based campaigns.
Cerberus commonly infects victims by masquerading as legitimate Android software, especially fake Adobe Flash Player installers, fake updates, media-player prompts, and other deceptive applications delivered outside official app stores. It has also been observed in campaigns using fake websites and COVID-19-themed Android lures. After installation, it abuses Android Accessibility Services to obtain extensive control over the device, facilitate overlay phishing, monitor foreground applications, and automate malicious actions.
Its core functionality is characteristic of advanced Android banking malware. Cerberus can launch overlay attacks against attacker-selected applications, generate fake notifications to lure victims into phishing flows, record keystrokes, collect SMS messages, send SMS messages, harvest contact lists, and enumerate installed applications. It communicates with command-and-control infrastructure over HTTP and supports exfiltration of stolen data. Reported capabilities from leaked builds and operational analyses also include screenshot capture, audio recording, location tracking, app download and removal, device locking, muting, Google Authenticator code theft, and call-related abuse. The malware’s control panel enabled operators to build payloads, manage infected devices, and review stolen information.
Cerberus also incorporates defense-evasion features. It has attempted to disable Google Play Protect, included anti-emulator and anti-analysis checks, and used device motion sensors such as the accelerometer or step counter to delay activation until the device appeared to be in real use rather than a sandbox or analyst environment. Some versions also included self-destruct functionality.
Operationally, Cerberus was heavily associated with financial targeting across multiple countries, including campaigns affecting users in Europe, the United States, and Japan. It developed numerous overlays for banking and other high-value applications, and it was part of the broader shift in Android banking malware toward accessibility-driven on-device fraud. Its public source-code leak significantly lowered the barrier to entry for other actors, enabling repurposed variants, private forks, and continued Android banking-trojan development well beyond the decline of the original Cerberus service.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Tools known as ‘cryptors’ are often used by malware authors... obfuscating or modifying their code to evade detection signatures.
Agent Smith can impersonate any popular application on an infected device, and the core malware disguises itself as a legitimate Google application.
provided a self-destruct mechanism to remove traces of the bot to prevent post-incident analysis.
Hercules automatically finds decryption key for actual DEX of the given Cerberus sample, decrypts it, then decrypts configuration parameters in the actual payload.
It uses the device's accelerometer to measure steps. 'The Trojan uses this counter to activate the bot,' ThreatFabric explains... This counter-measure 'prevents the Trojan from running and being analyzed in dynamic analysis environments (sandboxes) and on test devices.'
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
Given these permissions, many capabilities can be identified... Keylogging from within applications;
It uses the device's accelerometer to measure steps. 'The Trojan uses this counter to activate the bot,' ThreatFabric explains... This counter-measure 'prevents the Trojan from running and being analyzed in dynamic analysis environments (sandboxes) and on test devices.'
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
Given these permissions, many capabilities can be identified... Keylogging from within applications;
Most of the popular applications provide common stalkerware functionality such as: ... Taking screenshots
It uses almost identical data structures when communicating with the C2... Compared to the original Cerberus, ERMAC uses different encryption scheme in communication with the C2: the data is encrypted with AES-128-CBC
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the desired Android banking trojan or current equivalent with an administration panel.
Android banking trojan spread via fake COVID information apps requesting excessive permissions to exfiltrate personal data.
A named crypto drainer active in 2024, associated with phishing-based theft of cryptocurrency via malicious smart contract approvals.
Older Android banking trojan whose leaked source code was used as the basis for Perseus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.